CVE-2006-6945 Information
Feb 14, 2021
cve
Description
SQL injection vulnerability in Virtuemart 1.0.7 allows remote attackers to execute arbitrary SQL commands via unspecified vectors probably related to (1) Itemid (2) product_id and category_id parameters as handled in virtuemart_parser.php.
Reference
http://archives.neohapsis.com/archives/fulldisclosure/2007-01/0355.html http://secunia.com/advisories/24058 http://virtuemart.svn.sourceforge.net/viewvc/checkout/virtuemart/branches/virtuemart-1_0_0/virtuemart/CHANGELOG.php?revision=607 http://www.hackers.ir/advisories/festival.txt http://www.securityfocus.com/archive/1/459195/100/0/threaded http://www.securityfocus.com/bid/22123
Share on: